CVE-2026-24480 affects the QGIS repository’s GitHub Actions workflow named "pre-commit checks" prior to commit 76a693cd91650f9b4e83edac525e5e4f90d954e9. The workflow used the pull_request_target event and then checked out and executed code from the head of an external pull request. Because pull_request_target workflows execute in the security context of the base repository, including access to repository credentials and secrets, this created a condition where attacker-controlled pull request content could be run with elevated privileges. In practice, a malicious contributor could submit a crafted pull request whose code or workflow-invoked scripts would be executed by the CI job, resulting in arbitrary command execution in the privileged GitHub Actions runner context and potential compromise of the repository and associated secrets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
pull_request_target. Restrict or remove secrets and token permissions for workflows that may process external contributions, avoid checking out the PR head in privileged jobs, and separate untrusted validation tasks into low-privilege workflows such as those triggered by safer events where secrets are not exposed. Until fixed, maintainers could reduce risk by disabling the vulnerable workflow for external pull requests or requiring trusted review before any privileged workflow runs against contributor-controlled code.Patch, then assume compromise.
pull_request_target to execute untrusted pull request code. Workflows should avoid checking out or running code from the head of external pull requests in privileged contexts, and should instead use safer workflow designs that do not expose secrets or elevated repository credentials to attacker-controlled code.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.